Software Security: Industry Influencers

0 Likes     0 Followers     1 Subscribers

Sign up / Log in to like, follow, recommend and subscribe!

Recommendations


Episodes

Date Title & Description Contributors
2015-03-24

  Matthew McCullough on the Intersection of GitHub and Sonatype Nexus

Matthew McCullough is the director of field services at GitHub. While at DevNexus 2015 in Atlanta earlier this month, Matthew and I sat down with Brian Fox, VP of Product Management at Sonatype. The discussion was wide ranging, covering everything fro...
  Mark Miller, Trusted Software Alliance author
2014-06-10

  David A. Wheeler on the Current State of Application Security

"Typically, people divide the (software) world into cost, schedule, functionality, quality. In my experience, almost everyone when they talk 'quality', are excluding security." -- David Wheeler David Wheeler is a project leader at the Institute for De...
  Mark Miller, Trusted Software Alliance author
2014-05-06

  Omkhar Arasaratnam on Open Source Usage within the Large Enterprise

"I think with development practices, such as CI, we're going to get to a point that rather than having this one, monolithic milestone where you're given these hundreds of defects, instead the developer will have the ability to ingest these quality defe...
  Mark Miller, Trusted Software Alliance author
2014-04-30

  Dwayne Melancon, CTO - A Glimpse of the Future at Tripwire

At Source Conference in Boston last month, I sat down several times with Tripwire CTO Dwayne Melancon. Our discussion centered around his work with the development and engineering teams at Tripwire, their use of open source components, the future roadm...
  Mark Miller, Trusted Software Alliance author
2014-04-10

  Allison Miller and the Society for Information Risk Analysts

Allison Miller caught my attention at the end of her session at 2014 Source Boston when she 'Risk Rolled' the audience and had them sing along with a talking head embedded in her presentation. I knew immediately this was someone I wanted to talk with a...
  Mark Miller, Trusted Software Alliance author
2014-04-09

  2014 Source Boston - Bruce Schneier talks about the shift of power on the internet

'"It's only metadata" is a mischaracterization that plays into goverment hands.' -- Bruce Schneier At the 2014 Source Conference in Boston, I was able to sit down with Bruce Schneier after his keynote to clarify his position on several topics he broug...
  Mark Miller, Trusted Software Alliance author
2014-01-24

  Wayne Jackson - The Choices in Managing Software Security

"Increasingly, we're putting our lives on the line in software driven devices.From an industry perspective, we've got to start thinking about how we update these devices over time." -- Wayne Jackson I have been working with Sonatype as a community adv...
  Mark Miller, Trusted Software Alliance author
2013-11-06

  Curtis Yanko - Methodologies for Measuring the Cost of Software Defects

"There are ways through automation, design and testing techniques where we can take what is traditionally a three to six to nine week testing cycle and shrink it into minutes or hours." -- Curtis Yanko In November of 2013, I was able to catch up with ...
  Mark Miller, Trusted Software Alliance author
2013-10-24

  John Steven - Measuring the Cost of Application Security

"If you take the big, monolithic testing effort you currently have at the end, and you push it towards the beginning but it remains monolithic, you're not going to get the dramatic increase in efficiency and decrease in cost you expect. It has to be an...
  Mark Miller, Trusted Software Alliance author
2013-10-18

  Simon Bennetts - Web Applications Vulnerability Project

In this morning's news I saw a reference to a project on OWASP that documents the vulnerabilities in web applications and someone who is keeping a public repository of those vulnerabilities. I called and spoke with Simon Bennetts, co-lead of the projec...
  Mark Miller, Trusted Software Alliance author